Back to Feed
Threat IntelligenceSep 25, 2026

Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court

Kosovar national Ardit Kutleshi pleads guilty in US court for operating the Rydox cybercrime marketplace.

Summary

Ardit Kutleshi, a Kosovar national, has pleaded guilty in a US court to identity theft and money laundering conspiracy charges for his role in operating the Rydox cybercrime marketplace. The marketplace, which facilitated the trade of stolen PII, payment card data, credentials, and cybercrime tools, was disrupted in December 2024. Servers and approximately $225,000 in cryptocurrency were seized, and the domain www.Rydox.cc was taken down.

Full text

A Kosovar national pleaded guilty in a US court to charges related to the creation and administration of the Rydox cybercrime marketplace. The individual, Ardit Kutleshi, 28, was arrested in December 2024 along with two other suspects, Jetmir Kutleshi and Shpend Sokoli. He was extradited to the US last year. Rydox was disrupted in December 2024, when the US obtained judicial authorization to seize www.Rydox.cc, the domain that hosted the marketplace. The Rydox servers were also seized, along with roughly $225,000 in cryptocurrency. According to court documents, Rydox allowed cybercriminals to trade stolen personally identifiable information (PII), stolen payment card data, account credentials, and cybercrime tools. At least 321,372 cybercrime products were allegedly offered on Rydox, including stolen information such as names, addresses, credentials, credit cards, and Social Security numbers, along with phishing kits, stealer logs, and spamming tools. Rydox was estimated to have had approximately 18,000 users when taken down.Advertisement. Scroll to continue reading. More than 7,600 transactions were made through the marketplace between 2016 and 2024, and its operators received at least $232,000 in revenue. Kutleshi pleaded guilty to identity theft and money laundering conspiracy charges and is scheduled for sentencing on February 9, 2027. He faces two years of mandatory prison for the aggravated identity theft and up to 20 years in prison for money laundering. Related: US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks Related: AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft Related: In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw Related: NightmareStresser DDoS Service Disrupted in International Operation Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire SolarWinds Patches Critical RCE Flaws in Observability Self-HostedAstrana Health Data Breach Impacts Private, Confidential InformationCritical WordPress Vulnerability Exploited Immediately After DisclosureAdobe Patches Critical Flaws in Connect, AEM FormsChrome 154 Patches 108 VulnerabilitiesArista Urges Immediate Patching of Exploited VCO Zero-DayCritical F5 BIG-IP Vulnerability Exploited as Zero-DayCheck Point Patches Exploited Management Server Zero-Day Latest News CISA Election Security Plan Flags Patching Barriers, Voter Database AttacksWindows, Linux, Android File Notification Systems Leak User Activity‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data ExfiltrationRoundcube Webmail Vulnerability in Attackers’ CrosshairsAutonomous AI Hacks Raise Thorny Questions of Legal AccountabilityKontext Security Emerges With $4 Million for AI Agent Runtime ControlsOpenAI Agents Probed Websites for Vulnerabilities While Fetching Public DataAI-Powered Campaign Targets Hundreds of Online Retailers Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveDoppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.Delinea has appointed Timothy Regan as Chief Financial Officer.Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.More People On The MoveExpert Insights Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • domain — www.Rydox.cc

Entities

Ardit Kutleshi (threat_actor)Rydox (product)